CVE-2017-0144
BaseFortify
Publication date: 2017-03-17
Last updated on: 2025-10-22
Assigner: Microsoft Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | server_message_block | 1.0 |
| microsoft | windows_10_1511 | * |
| microsoft | windows_7 | * |
| microsoft | windows_8.1 | to 6.3.9600.20520 (inc) |
| microsoft | windows_server_2008 | * |
| microsoft | windows_server_2012 | * |
| microsoft | windows_vista | * |
| siemens | acuson_p300_firmware | 13.02 |
| siemens | acuson_p300_firmware | 13.03 |
| siemens | acuson_p300_firmware | 13.20 |
| siemens | acuson_p300_firmware | 13.21 |
| siemens | acuson_p300 | * |
| siemens | acuson_p500_firmware | va10 |
| siemens | acuson_p500_firmware | vb10 |
| siemens | acuson_p500 | * |
| siemens | acuson_sc2000_firmware | From 4.0 (inc) to 4.0e (exc) |
| siemens | acuson_sc2000_firmware | 5.0a |
| siemens | acuson_sc2000 | * |
| siemens | acuson_x700_firmware | 1.0 |
| siemens | acuson_x700_firmware | 1.1 |
| siemens | acuson_x700 | * |
| siemens | syngo_sc2000_firmware | From 4.0 (inc) to 4.0e (exc) |
| siemens | syngo_sc2000_firmware | 5.0a |
| siemens | syngo_sc2000 | * |
| siemens | tissue_preparation_system_firmware | * |
| siemens | tissue_preparation_system | * |
| siemens | versant_kpcr_molecular_system_firmware | * |
| siemens | versant_kpcr_molecular_system | * |
| siemens | versant_kpcr_sample_prep_firmware | * |
| siemens | versant_kpcr_sample_prep | * |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_10_1607 | to 10.0.14393.4467 (inc) |
| microsoft | windows_server_2016 | to 10.0.14393.4467 (inc) |
| microsoft | windows_rt_8.1 | to 6.3.9600.20520 (inc) |
| microsoft | windows_10_1507 | to 10.0.10240.18967 (inc) |
Helpful Resources
Exploitability
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability, known as CVE-2017-0144, affects certain versions of Microsoft Windows. It allows attackers to send specially crafted packets to the SMBv1 server, which can lead to the execution of arbitrary code. This means that an attacker could potentially take control of the affected system remotely.
How can this vulnerability impact me?
If your system is running one of the affected versions of Windows, this vulnerability could allow an attacker to gain unauthorized access to your computer. They could execute harmful actions, such as stealing data or installing malicious software, which could compromise your personal information and security.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?
This vulnerability could impact compliance with regulations like GDPR and HIPAA because it poses a risk to the security of personal and sensitive data. If an attacker exploits this vulnerability and gains access to protected information, it could lead to data breaches, which are serious violations of these regulations.
What immediate steps should I take to mitigate this vulnerability?
You should apply the patches provided by Microsoft for the affected versions of Windows. You can find more information and guidance on the official Microsoft security advisory page for CVE-2017-0144.